5.5
CVSSv3

CVE-2023-24056

Published: 22/01/2023 Updated: 03/02/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

In pkgconf up to and including 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pkgconf pkgconf

Vendor Advisories

Description<!---->A flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuplec:pkgconf_tuple_parse This issue may lead to a buffer overflow, which can crash the softwareA flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due ...